Terminal Services Client Configuration

Posted on 2004-04-30
Last Modified: 2010-04-19
I have two locations, main and an offsite, the offsite has speed issues over over the t1's so we installed and setup an Windows 2003 Terminal Server for use by those at the offsite. What we want to do is while they are at the offsite make the computers there into peusdo dummy terminals that will only allow them to log on to the Terminal Server, but if they came over to the main site it would act as a normal workstation on the network.

Basically comes down to how to force those worstations at the offsite to not give the option to logon to the normal desktop but only log onto the Terminal Server and give no access to the local machine.

Can this be done and how if possible?
Question by:MJDevos
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 16

Expert Comment

ID: 10959757
If you had 2 AD sites, then you could setup a GPO on the secondary site that locked down the desktops to this degree. However when they came to the other site, they would probably need a second reboot to refresh the GPO that allowed them access to the computer desktop.

Basically we are looking at a GPO that would take away all user access, except to the TS client and only then to you TS Server.

Yup, it can be done, using Site Based GPOs, configurable from AD Sites and Services snapin



Author Comment

ID: 10959810
Current configuration is that there is 1 Domain, I have worked with GPO but I have not seen any policies that would lock down the workstations to this degree. If it is configured from GPO then could you not make a AD group with just those computers and just apply the policy just to those computers?

Could you please show me where to look in GPO to set this up?

LVL 16

Accepted Solution

JamesDS earned 250 total points
ID: 10960264
You can't apply a GPO to a group and have it apply to those member of the group.

You CAN create a GPO for ALL machines or ALL users and filter it with group membership to only the machines or users you are interested in.

Look in the GPO settings for "allowed applications":
USER      Administrative Templates\System      Run only allowed Windows applications

Also consider a logon script that calls the TS client with a configuration file that connects them directly to your TS server.



Author Comment

ID: 10960512
You can apply GPO to a group, that is how we dictate what a normal, administrator, or all users are effected by the group policy.

We currently have groups that distinguish this, for example everyone will have Automatic Updates and Offline files govern by GPO, For normal users the machine will be locked down further, administrators will not be 'hindered' by the additional locked governed by the GPO. Then Terminal Server users will have a different desktop dictated by the local GPO rather than the domain GPO to differentiate the two.

Just depends on how you setup your GPO and with how many polices and if they can or can not be overriden. But to assign just to a group you do the following....

1. From AD right click over the domain and go to properties.
2. Click on the Group Policy Tab
3. Select the Group Policy you want to change
4. Click on the Properties button
5. Click on the Security tab
6. If this has never been changed then you will see the group 'Authenticated Users' this will include everyone normal or administrators. Remove this group, then add the group that you dictate that are to be govern by this GP and check Read Access and Apply Group Policy.

Other GP will or might override this GP depending on how you have them setup.


I will try this later today and possibly Monday and see if this will do what we need it to do. Thanks for the insight so far on the problem.
LVL 16

Expert Comment

ID: 10963014
You cannot apply a GPO to a group.

You can apply a GPO to a User or a Machine and filter the setting by using groups, but applying the GPO to an OU containing only groups will not have any effect. This is as you describe above, but the process is referred to as "GPO filtering using apply or deny groups"

Let me know how you get on with your changes



Featured Post

Business Impact of IT Communications

What are the business impacts of how well businesses communicate during an IT incident? Targeting, speed, and transparency all matter. Find out more in this infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit If you want to manage em…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question